If your organization holds an API Spec Q1 or API Spec Q2 certification, surveillance audits are an essential part of maintaining your certification and demonstrating ongoing compliance with API requirements. An API Spec Q1 & Q2 Surveillance Audit is not simply a routine inspection—it verifies that your Quality Management System (QMS) continues to operate effectively long after the initial certification has been achieved.
Many organizations focus heavily on preparing their initial certification audit but underestimate the importance of annual surveillance audits. As a result, corrective actions remain open, documentation becomes outdated, increasing the risk of using obsolete documents during audits and quality processes gradually drift away from documented requirements. A proactive approach helps organizations remain compliant, reduce operational risks, and prepare confidently for recertification.
This guide explains what an API surveillance audit is, why it matters, how the audit process works, what auditors typically review, common audit findings, and how to prepare your organization for an API surveillance audit activity effectively.
What Is an API Surveillance Audit?
A surveillance audit is a periodic, post-certification audit conducted by API (or an API-approved certification body) to confirm that your organization continues to meet the requirements of API Spec Q1 or API Spec Q2.
Unlike the initial certification audit, which evaluates the complete Quality Management System, a surveillance audit reviews all processes, records, and system elements to confirm that compliance is verify ongoing compliance rather than re-auditing everything from scratch.
Why Surveillance Audits Matter
API Certification Compliance is not a one-time achievement. API requires organizations to continually demonstrate compliance throughout the certification cycle.
Surveillance audits for any API Certification, help organizations:
-
- Verify continued compliance with API requirements.
- Ensure Quality Management Systems remain effective.
- Identify process weaknesses before they become major nonconformities.
- Demonstrate commitment to continual improvement.
- Build customer confidence.
Year 1 Surveillance Audit
The first surveillance audit reviews all processes and verifies that corrective actions from the certification audit have been effectively implemented.
Year 2 Surveillance Audit
A second surveillance audit evaluates all clauses and processes to ensure continued compliance across the Quality Management System.
Year 3 Recertification Audit
A full system audit is conducted to renew certification for the next three-year cycle.
How Long Does a Surveillance Audit Take?
Surveillance audits are generally shorter than initial certification or recertification audits —often 1 day to a few days, depending on:
-
- The size and complexity of your organization
- Number of locations/sites within scope
- Findings from previous audits (more open nonconformities can extend audit duration)
- Changes in scope or processes since the last audit
What Does an API Surveillance Audit Cover?
Corrective Actions
Auditors review previous nonconformities to confirm that corrective actions have been implemented, root causes identified, and recurring issues prevented.
Internal Audits and Management Review
Organizations are expected to conduct regular internal audits and management reviews throughout the certification cycle.
Auditors verify that:
-
- Internal audits are completed according to the schedule.
- Findings are documented.
- Correction and Corrective actions are monitored.
- Management reviews evaluate system performance and drive continual improvement.
These activities provide evidence that the Quality Management System is actively maintained between certification audits.
Monogram/Mark Usage (if applicable)
For organizations licensed to use the API Monogram, auditors confirm the mark is being applied correctly and only to conforming to products.
Organizational Changes
Any changes to your scope of certification, key personnel, facilities, or processes since the last audit are reviewed for impact on compliance.
Product or Service Conformance sample
Especially under API Q1, auditors may pull samples of manufactured products or production records to verify conformance to the applicable API product specification (e.g., API 6A, API 5CT, API 7-1)
For service organizations, auditors typically review service planning, competency records, execution records, risk assessments, and service validation activities.
Common Reasons Organizations Fail Surveillance Audits
Despite having an established Quality Management System, organizations often receive nonconformities because routine processes are not consistently followed between certification audits. Some of the most common findings include:
-
- Corrective actions from previous audits that remain incomplete or ineffective a common issue explained in our guide on why API Q1 certification fails in Year 2 instead of Year 1
- Weak internal audit programs that fail to identify meaningful issues.
- Outdated procedures that no longer reflect current practices and changes in applicable standards.
- Incomplete or inconsistent records across departments.
- Poor supplier evaluation and monitoring.
- Gaps in competency and training records.
- Inadequate risk assessments following organizational or operational changes.
- Weak traceability of products, materials, or service activities.
- Lack of QMS induction to new employees
Identifying and addressing these issues early helps organizations maintain compliance and reduces the likelihood of major nonconformities during an API Q1 Q2 surveillance audit.
How to Prepare for an API Surveillance Audit: Step-by-step guide
Preparing for an API Spec Q1 or Q2 surveillance audit isn’t about last-minute paperwork — it’s about proving that your QMS runs the same way whether an auditor is watching or not. Use this checklist as a working framework throughout the year, not just in the weeks before your audit date.
Close out prior nonconformities early
Don’t wait until the week before the audit to address findings from your last surveillance or certification audit. Auditors specifically check whether corrective actions were resolved promptly and effectively, with genuine root cause analysis — not just a quick documentation fix. Organizations that close out nonconformities within 30–60 days of the previous audit consistently perform better on subsequent surveillance visits, since it demonstrates a functioning corrective action process rather than reactive compliance.
Run a mock internal audit
Before the official surveillance audit, conduct an internal audit focused specifically on the clauses most likely to be sampled during this cycle. Since surveillance audits rotate coverage across API Q1/Q2 clauses over the 3-year cycle, reviewing your audit history and certification body’s sampling plan can help you predict which processes — design control, purchasing, production, or risk management — are due for scrutiny. A well-run mock audit surfaces gaps while there’s still time to fix them.
Review your management review minutes
Ensure QMS performance data, risk assessments, and quality objectives are being genuinely discussed in management review meetings — not just documented as a formality. Auditors look for evidence that leadership is actively engaged with the QMS, using metrics like nonconformity trends, customer complaints, and audit results to drive real decisions and continuous improvement, not simply signing off on a template.
Audit your own document control
Confirm that the latest approved procedure revisions are in use at the point of work — on the shop floor, in the field, and at every workstation — not just archived correctly in your document management system. A common surveillance audit finding is outdazted by procedures still being followed in practice while a newer revision sits unused in the system. Spot-check multiple departments and shifts to catch this before the auditor does.
Check customer complaint logs
Review your complaint records for completeness, timeliness, and evidence of thorough root cause analysis and corrective action. Surveillance auditors treat customer complaints as a real-world signal of how well your QMS is actually functioning, so incomplete or superficially resolved complaints are a red flag that can trigger deeper questioning into related processes.
Verify Monogram/mark usage
If your organization holds an API Monogram license, confirm the mark is being applied correctly and exclusively to conforming products, packaging, nameplates, and certificates of conformance. Misuse or inconsistent application of the Monogram is one of the fastest ways to draw a major nonconformity, since it directly affects the integrity of the certification mark in the marketplace.
Brief key personnel
Make sure staff across departments — not just the quality manager — can confidently and accurately describe their own processes to an auditor. Surveillance auditors frequently interview production, engineering, and field personnel directly, and inconsistent answers between what’s documented and what employees actually do is one of the most common sources of findings. A short pre-audit briefing on expected questions and process ownership goes a long way.
Review any organizational changes
Any changes to your certified scope, facilities, key personnel, subcontractors, or processes since the last audit need to be reflected in your quality manual and scope statement before the auditor arrives. Unreported organizational changes can create scope discrepancies that auditors are specifically trained to flag, potentially triggering additional audit time or follow-up requirements.
What Happens if Nonconformities Are Found During a Surveillance Audit?
If nonconformities are identified during the surveillance audit, the organization is expected to take timely corrective action.
The typical process includes:
- The auditor documents the nonconformity and explains the applicable requirement.
- The organization performs a root cause analysis to determine why the issue occurred.
- A corrective action plan is submitted within the timeframe specified by the certification body.
- Evidence of implementation may be reviewed before the finding is closed.
If a nonconformity from a previous surveillance audit is repeated, it indicates that the earlier corrective action was ineffective or not fully implemented. In such cases, auditors will assess the effectiveness of the organization’s root cause analysis, evaluate whether the issue is systemic, and may raise a more serious nonconformity.
Failure to address major nonconformities—or repeated recurrence of the same issues—may result in suspension of certification. Persistent or unresolved nonconformities can ultimately lead to the withdrawal of certification
Best Practices for Staying Audit Ready
Successful organizations treat surveillance audits as part of their continual improvement process rather than an annual event.
Recommended practices include:
-
- Conduct internal audits within 12 months as per plan instead of immediately before surveillance audits.
- Monitor corrective actions until they are fully implemented and verified.
- Outdated procedures that no longer reflect current practices and changes in applicable standards.
- Regularly review quality objectives and management review outputs.
- Maintain accurate records and document control.
- Train employees on their responsibilities within the Quality Management System.
- Encourage continual improvement across all departments.
Maintaining these practices helps organizations demonstrate consistent compliance and reduce audit-related risks.
Organizations holding an API Monogram license should remember that surveillance audit findings play a key role in maintaining compliance. Addressing nonconformities promptly helps ensure a smooth API Monogram license renewal process.
Frequently Asked Questions
Surveillance audits are typically conducted annually during the three-year certification cycle to verify continued compliance with API Spec Q1 or API Spec Q2 requirements.
API Spec Q1 surveillance audits verify that manufactured products consistently meet API requirements. API Spec Q2 surveillance audits verify that services are planned, controlled, and delivered consistently to meet customer and API requirements.
A surveillance audit verifies that your Quality Management System (QMS) is being effectively maintained and implemented. The following documents should be readily available:
-
- Current QMS documents and controlled procedures
- Previous audit reports and evidence of corrective action closure
- Records covering the period since the last API audit
- Internal audit reports
- Management review meeting minutes
- Manufacturing, inspection, and testing records
Yes. Significant or unresolved nonconformities may result in suspension or withdrawal of certification if corrective actions are not completed within the required timeframe.
